{
  "Name": "Cyfirma Attack Surface",
  "Author": "Microsoft",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Cyfirma_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The CYFIRMA Attack Surface solution provides ability to gain continuous visibility into their external digital footprint directly within Microsoft Sentinel. This integration enhances your security posture by identifying exposed assets, misconfigurations, and vulnerabilities across internet-facing infrastructure—enabling faster response to potential threats and reducing the attack surface before adversaries can exploit it. By ingesting enriched attack surface intelligence—covering open ports, vulnerable IPs, cloud misconfigurations, certificate issues, and more—into Microsoft Sentinel, security teams can correlate findings with other threat indicators, automate incident response, and drive proactive defense measures.",
  "Analytic Rules": [
    "Analytic Rules/ASCertificatesHighRule.yaml",
    "Analytic Rules/ASCertificatesMediumRule.yaml",
    "Analytic Rules/ASCloudWeaknessHighRule.yaml",
    "Analytic Rules/ASCloudWeaknessMediumRule.yaml",
    "Analytic Rules/ASConfigurationsHighRule.yaml",
    "Analytic Rules/ASConfigurationsMediumRule.yaml",
    "Analytic Rules/ASDomainIPreputationsHighRule.yaml",
    "Analytic Rules/ASDomainIPreputationsMediumRule.yaml",
    "Analytic Rules/ASDomainIPVulnerabilitiesHighRule.yaml",
    "Analytic Rules/ASDomainIPVulnerabilitiesMediumRule.yaml",
    "Analytic Rules/ASOpenPortsHighRule.yaml",
    "Analytic Rules/ASOpenPortsMediumRule.yaml"
  ],
  "Parsers": [],
  "Data Connectors": [
    "Data Connectors/CyfirmaASAlerts_ccp/CyfirmaASAlerts_DataConnectorDefinition.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Cyfirma Attack Surface",
  "Version": "3.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}